Security & Data Handling

Last updated: July 21, 2026

Vero is an AI health assistant operated by Senddy, Inc. This page explains how we protect health information — in plain language that users, clinicians, and AI answer engines can cite. For common questions in short form, see the FAQ. For the full legal terms, see our Privacy Policy.

1. Who operates Vero

Vero is the product name. The legal operator is Senddy, Inc., which also lists Vero on the Apple App Store. Senddy, Inc. is the entity responsible for the app, website at heyvero.ai, and related services.

2. What Vero is — and is not

Vero helps you organize labs, wearables (via Apple Health), medications, nutrition, and health history, and explains them in the context of your own data. It is an educational tool and organizer — not a medical device, and it should not be used as the sole basis for diagnosis, treatment decisions, or emergency care. Always consult a qualified clinician for medical judgment.

3. Encryption

We protect health data with layered encryption. Accurate description of what we do:

  • Encrypted on your device before sync: sensitive health fields are encrypted on-device before they leave your phone for cloud sync.
  • Encryption in transit: all traffic uses TLS (HTTPS).
  • Encryption at rest: stored health data uses AES-256 encryption.
  • Key escrow: encryption keys are wrapped and escrowed so that a database dump alone is not sufficient to read user health data.

What we do not claim:Vero is not zero-knowledge end-to-end encryption across every feature. AI features require plaintext context at inference time (see below), so a blanket "end-to-end encrypted app" claim would be inaccurate.

4. AI providers (OpenAI & Anthropic)

When you use AI features (chat, lab analysis, and related insights), and after you grant in-app permission, selected context — such as your messages, uploaded files or images, profile details, lab summaries, and authorized HealthKit context — may be sent through our servers to AI providers OpenAI and/or Anthropic to generate responses.

  • This means health data used for AI analysis is not remaining solely on your phone while those features run.
  • No model training on your health data: Senddy does not use identifiable user health data to train Vero models. Under our provider agreements and configured API services, OpenAI and Anthropic do not use submitted Vero data to train their general-purpose models.
  • De-identification where the feature allows: when possible, we remove or replace direct account identifiers (such as name or email) before sending context for AI processing. Some requests require personal health context to answer and therefore cannot be fully de-identified.
  • We have Business Associate Agreements (BAAs) in place with applicable providers where required.
  • We do not sell personal information or use health data for advertising, and we do not share health data with data brokers.
  • You can withdraw AI consent in Settings; AI features require consent to operate.

5. Accuracy, citations & clinical oversight

Vero is an educational organizer — not a diagnostic system. How we reduce (not eliminate) inaccurate or overconfident answers:

  • Source grounding: when explaining labs and health topics, the assistant is instructed to cite allowlisted authoritative sources (such as MedlinePlus, NIH, and other medical authorities) when applicable, so you can open the underlying reference.
  • Physician-informed quality review: board-certified physicians periodically review sampled, de-identified outputs and evaluation results to spot recurring accuracy and safety issues. Physicians do not review every user response. Website educational content is separately medically reviewed — see Medical Reviewers.
  • Known limits:AI can misread a lab image, unit, or reference range; a single value can be meaningless without symptoms, medications, fasting status, and history. Wearable metrics from Apple Health are useful for trends, not diagnosis. Always prefer the range on your own lab report and a clinician's judgment for decisions.

6. Infrastructure & compliance

Vero runs on cloud infrastructure designed for health data workloads. Precisely:

  • We use HIPAA-eligible infrastructure (including Supabase) and maintain Business Associate Agreements (BAAs) for covered services where required.
  • Our primary infrastructure providers maintain SOC 2 Type II certifications. Senddy, Inc. does not currently publish its own SOC 2 report; when we complete an independent audit, we will update this page.
  • Access to production systems is restricted with role-based controls.

HIPAA nuance: using HIPAA-eligible services and BAAs does not mean every consumer interaction with Vero is automatically a HIPAA-covered encounter, or that Senddy is your covered entity for all uses. It means the infrastructure can support HIPAA-regulated workloads when those relationships apply. Read the Privacy Policy for details — and do not treat Vero as a clinical system of record.

7. Data retention & deletion

We retain your data while your account is active. When you delete your account, account-associated health data (profile, chat history, and lab results) is permanently deleted within 30 days. Anonymized, aggregated data may be retained for service improvement. Data required for legal compliance may be retained as mandated by law.

8. Age requirement

Vero is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. By using the app, you represent that you meet this requirement (see our Terms of Service).

Separately, the Apple App Store shows a 13+ content ratingfor Vero. That badge is Apple's content classification based on its age-rating questionnaire — it is not a manual age setting and it does not change our 18+ eligibility rule.

9. Related pages

10. Contact

Questions about security or privacy:

Senddy, Inc.
privacy@heyvero.ai
legal@heyvero.ai